Description
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).
Problem types
Product status
Any version
Timeline
| 2025-05-20: | Reported to Red Hat. |
| 2025-05-20: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-4969
bugzilla.redhat.com/show_bug.cgi?id=2367552 (RHBZ#2367552)
gitlab.gnome.org/GNOME/libsoup/-/issues/447